CVE-2026-67427 | flytohub flyto-core up to 2.26.5 Workflow Engine Variable Resolver env.get/env.load_dotenv workflow parameter permission assignment

SecurityVulns

A vulnerability was found in flytohub flyto-core up to 2.26.5 and classified as problematic. The impacted element is the function env.get/env.load_dotenv of the component Workflow Engine Variable Resolver. Such manipulation of the argument workflow parameter leads to incorrect permission assignment.

This vulnerability is listed as CVE-2026-67427. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More